MGASA-2018-0432
Dashboard / Vulnerabilities / MGASA-2018-0432
Summary: Updated mbedtls packages fix security vulnerabilities
Details: Updated mbedtls package fixes security vulnerabilities: Fixed a vulnerability in the TLS ciphersuites based on use of CBC and SHA-384 in DTLS/TLS 1.0 to 1.2, that allowed an active network attacker to partially recover the plaintext of messages under certains conditions by exploiting timing side-channels (CVE-2018-0497). Fixed a vulnerability in TLS ciphersuites based on CBC, in DTLS/TLS 1.0 to 1.2, that allowed a local attacker, with the ability to execute code on the local machine as well as to manipulate network packets, to partially recover the plaintext of messages under certain conditions (CVE-2018-0498). Fixed an issue in the X.509 module which could lead to a buffer overread during certificate extensions parsing (no CVE assigned).
References: https://advisories.mageia.org/MGASA-2018-0432.html, https://bugs.mageia.org/show_bug.cgi?id=23660, https://tls.mbed.org/tech-updates/releases/mbedtls-2.12.0-2.7.5-and-2.1.14-released, https://tls.mbed.org/tech-updates/releases/mbedtls-2.13.0-2.7.6-and-2.1.15-released
Affected packages
Package
Name: mbedtls
Purl: pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
